Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m2r5-4w96-qxg5

Опубликовано: 28 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml

Impact

It's possible in a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service.

For example:

{{velocity}} #set($xml=$services.get('xml')) #set($xxe_payload = "<?xml version='1.0' encoding='UTF-8'?><!DOCTYPE root[<!ENTITY xxe SYSTEM 'file:///etc/passwd' >]><root><foo>&xxe;</foo></root>") #set($doc=$xml.parse($xxe_payload)) $xml.serialize($doc) {{/velocity}}

Patches

The problem has been patched on versions 12.10.10, 13.4.4 and 13.8RC1.

Workarounds

There's no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

References

https://jira.xwiki.org/browse/XWIKI-18946

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

org.xwiki.commons:xwiki-commons-xml

maven
Затронутые версииВерсия исправления

>= 2.7, < 12.10.10

12.10.10

Наименование

org.xwiki.commons:xwiki-commons-xml

maven
Затронутые версииВерсия исправления

>= 13.0.0, < 13.4.4

13.4.4

Наименование

org.xwiki.commons:xwiki-commons-xml

maven
Затронутые версииВерсия исправления

>= 13.5-rc-1, <= 13.7

13.8-rc-1

EPSS

Процентиль: 32%
0.00127
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 4.9
nvd
почти 4 года назад

org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server with XML External Entity Injection through the XML script service. The problem has been patched in versions 12.10.10, 13.4.4, and 13.8-rc-1. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.

EPSS

Процентиль: 32%
0.00127
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-611